すべての従業員、請負業者、およびサードパーティのユーザーが組織のセキュリティ プログラムに関する正式なコミュニケーションを確実に受け取るために最も役立つポリシーのタイプはどれですか?
正解:C
The information security training policy ensures that everyone within the organization, including contractors and third-party users, receives the appropriate level of security awareness and training. This policy defines how the organization communicates its security requirements, expectations, and best practices.
"Information security training policies and programs ensure that all personnel are aware of and understand the security requirements and their individual responsibilities."
- CISM Review Manual 15th Edition, Chapter 3: Information Security Program Development and Management, Section: Security Awareness and Training The ISACA CISM practice questions emphasize that a clear training policy is the best way to communicate security practices to all involved parties.